CVE-2024-23369

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 119

Summary

CVE-2024-23369 is a newly disclosed memory corruption vulnerability. It affects the handling of HLOS (Hypervisor-Based Local Out-of-Band Services) input for FRS/UDS (Flexible Real-Time Transport Protocol for Automotive Diagnostic and Communications) request/response buffers. An attacker who can provide invalid length data to the HLOS may successfully corrupt the memory of the affected system, potentially leading to unintended execution of code or a denial-of-service condition. Systems utilizing FRS/UDS protocols and interacting with HLOS are at risk and should be promptly patched to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share